Threat researchers reported separate malware campaigns that used fake or pirated software distribution channels to infect Windows users with credential theft and traffic-interception malware. In one campaign, attackers seeded cracked software sites with a trojanized WinX_DVD_Copy_Pro.exe that launched an obfuscated HTA through MSHTA, deployed an upgraded CountLoader v3.2, and ultimately delivered ACR Stealer entirely in memory. The loader established persistence with scheduled tasks, profiled infected hosts, authenticated to command-and-control with a JWT token, and supported additional payload delivery through ZIP, DLL, MSI, PowerShell, and removable-media propagation tasks.
A second campaign abused interest in DeepSeek-R1 by promoting a fake DeepSeek site through Google Ads and delivering a malicious installer, AI_Launcher_1.21.exe, backed by fake CAPTCHA pages, PowerShell, AES-decrypted payloads, and a domain-generation routine. The final malware, BrowserVenom, installed a rogue root certificate and reconfigured browsers to send traffic through the attacker-controlled proxy 141.105.130[.]106:37121, allowing interception and collection of user web activity. Researchers said the operations relied on impersonation-themed infrastructure and low-detection payloads to evade defenses, with BrowserVenom infections observed in Brazil, Cuba, Mexico, India, Nepal, South Africa, and Egypt.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Howler Cell reported related malicious Python packages associated with the CountLoader activity had been seen since September 2025. The packages had zero antivirus detections at the time they were uploaded.
Kaspersky GReAT published research describing a malvertising campaign that abused DeepSeek-R1 branding to lure users to a fake DeepSeek website promoted through Google Ads. The report detailed delivery of the AI_Launcher_1.21.exe installer and the BrowserVenom implant that installed a rogue root certificate and forced browsers through a malicious proxy.
Howler Cell uncovered a malware campaign using cracked software distribution sites and a multistage infection chain to deploy CountLoader v3.2. In the observed activity, the loader ultimately delivered ACR Stealer via a trojanized WinX_DVD_Copy_Pro.exe unpacked entirely in memory.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.